Chapter 06 · Part II · Moving data

Your home network

Somewhere in your house there's a blinking box, maybe two or three, and everyone calls one of them "the modem." Inside that plastic are five or six separate jobs: translating the line, routing, address translation, handing out addresses, answering name lookups, guarding the door, and running the Wi-Fi. Knowing which box does which job is the difference between guessing and fixing.

1 public addressis what most homes get from the ISP for IPv4; every device in the house shares it through NAT
3 clear channelsat 2.4 GHz in North America: 1, 6 and 11 are the only 20 MHz channels that don't overlap
TTL − 1 per routerevery router a packet crosses lowers its time-to-live by one; switches, access points and modems don't touch it

Common mix-up: the box your ISP gave you is rarely "just a modem." It's usually a gateway: modem, router, NAT, DHCP server, firewall, switch and Wi-Fi in one case. Plug your own router in behind it without changing anything, and you now have two routers each doing NAT, one behind the other. That's double NAT, and it's the most common home network problem nobody notices.

The cast

Six jobs, usually one box

A home network is a small version of every network in this course. It has a link to the outside world, a border where your private addresses meet the public internet, a local segment where your devices talk to each other, and a radio that stretches that segment through the air. In an office each of those is a separate machine in a rack. At home they are usually squeezed into one or two boxes, which is why it's hard to tell them apart.

It helps to name the jobs before naming the boxes:

  • Modem or ONT. Turns whatever your ISP's line carries (radio frequencies on coax, tones on a phone line, pulses of light on fiber) into ordinary Ethernet. It makes no decisions about addresses.
  • Router. Sits on the border between your network and the ISP's. It decides where each packet goes next, and at home it also does NAT, runs the DHCP server, forwards DNS questions, and keeps a firewall.
  • Switch. Gives you more Ethernet ports on the same network and delivers each frame only to the port it's meant for.
  • Access point. A switch port made of radio. It carries the same local network over Wi-Fi.
  • Mesh. Several access points that cooperate, so one network name covers the whole house.

The layer model from Chapter 01 sorts them neatly. The modem works at layers 1 and 2: signals and frames. The switch and the access point work at layer 2: they read MAC addresses and nothing else. The router is the first box that reads IP addresses, layer 3, and because it does NAT it also reads and rewrites port numbers, which belong to layer 4. That one fact explains most of what follows: only the boxes that work at layer 3 change your packet's IP header. The others just carry it.

BoxLayerReadsChanges in your packet
Modem / ONT1–2The line signalOnly the outer framing (Ethernet in, DOCSIS or GPON out)
Switch2Destination MACNothing
Access point / mesh point2MAC addressesRe-wraps an 802.11 radio frame as an Ethernet frame
Router3 (+4 for NAT)Destination IP, portsNew MAC addresses, TTL − 1, and with NAT the source address and port
ISP gateway, router mode1–7EverythingAll of the above, in one case
ISP gateway, bridge mode1–2The line signalBehaves like a plain modem
The edge of your house

Modem and ONT: speaking the line

Your ISP's cable doesn't carry Ethernet. Cable internet runs over the same coax as cable TV, using a standard called DOCSIS that packs data into radio-frequency channels. DSL uses high-frequency tones on a telephone pair. Fiber uses light, and on most home fiber the box on your wall is an ONT, an optical network terminal, that speaks a passive optical network standard such as GPON, where one fiber from the street is split among a few dozen homes. Fixed wireless and 5G home internet use a radio on the roof or the windowsill.

Whatever the medium, the job is the same: a modem (modulator-demodulator, the old name from the dial-up days) turns the line's signal into Ethernet frames on one side and back again on the other. It is a translator between two physical worlds. It doesn't route, it doesn't hand out private addresses, it doesn't block anything. If you plug a single computer straight into a plain modem, that computer asks the ISP for an address by DHCP, gets the public address, and is directly on the internet with nothing in front of it.

That's why a modem is almost always followed by a router. The router plugs into the modem with its WAN port (wide area network, "the outside"), gets the public address from the ISP, and builds your private network on its LAN ports.

Go deeper: CGNAT, when even your "public" address isn't

IPv4 addresses ran out years ago, and some ISPs (most mobile carriers, many 5G home and some fiber providers) no longer give each customer a public one. Instead your router's WAN port gets an address from 100.64.0.0/10, a block RFC 6598 set aside as "shared address space" for exactly this, and the ISP runs its own large NAT, carrier-grade NAT, in front of thousands of customers. Your traffic gets translated twice: once by your router, once by the carrier.

You can spot it in your router's status page: if the WAN address starts with 100. and the second number is between 64 and 127, you're behind CGNAT. (One catch: Tailscale also uses addresses from that same block for its own devices, so a 100.x address on a Tailscale adapter means something different.) Chapter 08 covers what CGNAT does to port forwarding.

The border

The router does five jobs

A home router is the busiest box in the house. Strictly, "routing" is only the first of its jobs. The others ride along because the router is the one place every packet to and from the internet has to pass.

  1. Routing. Your router's routing table is tiny. It has one route for the local network ("192.168.1.0/24: deliver directly on the LAN") and one default route ("everything else: send to the ISP"). That's the whole table. Chapter 10 shows what a big one looks like.
  2. NAT. Your devices have private addresses from RFC 1918 ranges like 192.168.0.0/16, which are not allowed on the public internet. On every outgoing packet the router swaps your device's address and port for its own public address and a port of its choosing, and writes the swap in a table so it can undo it when the reply comes back. Chapter 07 is all about that table.
  3. DHCP server. It lends every device that joins an address, the mask, the default gateway (itself) and a DNS server (usually itself again). Chapter 04 walks the four-message exchange.
  4. DNS forwarder. It accepts your devices' name lookups, passes them to the ISP's resolver or whichever one you configured, and caches the answers.
  5. Firewall. It lets replies to conversations you started come back in, and drops anything that arrives unasked. On IPv4 the NAT table does much of this by accident, since an unsolicited packet has no table entry to match. A real stateful firewall does it on purpose, and it's what protects you on IPv6, where there's usually no NAT at all.

Most routers also contain a small switch, typically four LAN ports, and one or two Wi-Fi radios. So "the router" in everyday speech is really router, switch and access point together. The thing to keep straight is which of those jobs is happening where, because the router part is the only part that changes addresses.

192.168.86.57:51514 → 203.0.113.45:51514
NAT on the way out: your laptop's private address and port become the router's public address and a port it picks. The reply is translated back by looking up that port.
Go deeper: what a router does to every packet it forwards

RFC 1812, the requirements document for IPv4 routers, spells it out. A router receives a frame, checks that it's addressed to its own MAC address, unwraps the IP packet, and looks up the destination in its routing table. It lowers the TTL by one; if that makes it zero, it throws the packet away and sends an ICMP "time exceeded" message back to the sender. Then it recalculates the header checksum (it changed a field), finds the MAC address of the next hop with ARP, and wraps the packet in a fresh frame for the next link.

So even without NAT, the layer-2 envelope is brand new after every router, and one IP header field always changes. NAT adds two more: the source address and source port on the way out, and the destination address and port on the way back. Instrument 2 below shows each change happening, hop by hop.

On IPv6 the ISP usually hands your router a whole block of addresses by DHCPv6 prefix delegation (commonly a /56 or /64), and every device gets a real global address. RFC 7084 lists the basic requirements for these home routers, and RFC 6092 describes the default "outbound allowed, unsolicited inbound blocked" firewall they're expected to run instead of NAT.

Instrument 1

The home network map

Click any box to see what it does and which layer it works at. Use the presets or the switches to rearrange the house. The shaded bands are address spaces; every box marked NAT starts a new one. Watch the laptop's packet travel left: its source address changes each time it leaves through a NAT. Put the ISP gateway in bridge mode and one NAT disappears.

NAT layers–
Laptop address · gateway–
Public address lives on–
tracert first hops–

Addresses are typical defaults: 192.168.1.0/24 on the ISP gateway, 192.168.86.0/24 on the mesh router, a documentation address standing in for the public one.

Inside the house

Switch, access point, mesh

Inside your network, devices talk to each other with Ethernet frames addressed by MAC address, as Chapter 02 explains. A switch learns which MAC address lives behind which port by watching the source address of every frame that arrives, and from then on sends each frame only out the right port. It never looks at IP addresses. A cheap unmanaged five-port switch behind your TV is just a way to turn one wall jack into four, and every device plugged into it is on exactly the same network as everything else.

An access point does the same thing with radio. Your laptop sends an 802.11 frame through the air; the access point receives it and re-sends the same data as an Ethernet frame on its wired side, and the reverse for traffic coming back. That makes it a bridge between two kinds of layer 2. Your laptop's IP address, the router's address, the TTL: none of it changes. A device on Wi-Fi and a device on a cable, both behind the same router, are neighbors on one subnet.

A mesh system is several access points that coordinate. One unit, the main one, usually also acts as the router. The others, satellites or "points," connect back to it either by cable or by Wi-Fi itself (the backhaul), and they all broadcast the same network name, so your phone can roam from one to the next. Mesh points are bridges too: adding a third or fourth one never adds another NAT, only more coverage.

The trouble starts when a box that could be a router is installed where only a bridge was needed. Most mesh kits and retail routers come out of the box in router mode, with NAT and a DHCP server switched on. Put one behind an ISP gateway that's also in router mode and you get two routers in a row. Most of these products offer a "bridge mode" or "access point mode" that turns their router functions off, and that, or turning the ISP gateway's off instead, is usually the fix.

Go deeper: three addresses in a Wi-Fi frame

An Ethernet frame has two addresses, source and destination. An 802.11 data frame in a normal home network carries three: the radio that sent it, the radio that should receive it, and the final destination or original source on the wired side. When your laptop sends to the router through an access point, the frame says "from laptop, to access point (the BSSID), final destination router." The access point copies the laptop and router addresses into an ordinary Ethernet frame. The fourth address field exists for wireless-to-wireless bridging, which is what some mesh backhaul links use.

Wireless backhaul has a cost. A mesh point with one radio has to receive your data over the air and then send it again over the air to the main unit, on the same channel, so the airtime is used twice. Tri-band mesh systems put the backhaul on a separate radio to avoid that. A cable between mesh points, if your house has one, beats both.

Through the air

Wi-Fi: bands, channels, and walls

Wi-Fi is radio, and the physics deserves a whole chapter. The companion site already has one: waves.jelia.nyc/2-4-ghz walks through what a 2.4 GHz wave is, why water and walls absorb it, and how antennas send it. Here is the network engineer's short version.

Three bands. Home Wi-Fi uses the 2.4 GHz band, the 5 GHz band and, with Wi-Fi 6E and Wi-Fi 7 equipment, the 6 GHz band. Each band is divided into channels. Two networks on the same channel take turns using the air; two on overlapping channels interfere with each other in a messier way.

2.4 GHz is crowded. Its channels are only 5 MHz apart, but a Wi-Fi signal is about 20 MHz wide, so neighboring channel numbers overlap. In North America that leaves 1, 6 and 11 as the only three that don't. Microwave ovens, Bluetooth and every neighbor's router share the same small slice. In exchange, 2.4 GHz reaches farther and gets through walls better.

5 GHz and 6 GHz are roomy. Far more channels, and they can be bonded into wider ones (40, 80, 160 MHz, and 320 MHz in Wi-Fi 7 at 6 GHz) for more speed. The price is range. Higher frequencies generally lose more of their strength going through walls, floors and furniture, so a 5 GHz signal that's excellent in the same room may be weak two rooms away. Some 5 GHz channels, the DFS channels, are shared with weather and military radar, and a router using them must listen for radar and move off if it hears any.

Why walls matter. Signal strength falls off with distance even in open air, and every wall takes another bite. Drywall takes a little, brick and concrete a lot, metal, mirrors and foil-backed insulation nearly everything. A water heater or a fish tank in the way is a surprisingly good shield. That's the whole case for mesh: rather than one loud radio shouting through four walls, put a quieter one in each part of the house.

BandChannel widthsStrengthWeakness
2.4 GHz20 MHz (40 rarely useful)Range, gets through walls, every device supports itOnly 3 non-overlapping channels; crowded; slowest
5 GHz20 / 40 / 80 / 160 MHzMany channels, much fasterShorter reach; DFS channels may switch when radar is detected
6 GHzup to 160 MHz; 320 MHz with Wi-Fi 7Wide, clean channels; only newer devices, so little congestionShortest reach of the three; needs Wi-Fi 6E or 7 devices
Go deeper: why "1,200 Mbps" Wi-Fi isn't

The number on the box is the PHY rate: the fastest a single device could signal under perfect conditions, at the widest channel, with every antenna stream in use. Real throughput is often half that or less. Part of the gap is overhead: every frame waits a random backoff before sending (Wi-Fi's medium access method is CSMA/CA, carrier sense with collision avoidance), and every unicast frame gets an acknowledgment. Part is distance, since the radio drops to slower, more robust encodings as the signal weakens. And part is sharing: all devices on a channel take turns, including your neighbors'.

Wi-Fi on a given channel is half-duplex: one radio talks at a time. Switched Ethernet is full-duplex: each cable carries traffic in both directions at once, and a switch gives each port its own collision-free link. That's the root of the wired-versus-wireless difference below.

Cable or air

Wired versus wireless

Both are layer 2; both carry exactly the same IP packets. The difference is in how predictable the trip is.

  • Speed. Gigabit Ethernet (1000BASE-T) delivers close to its full 1 Gb/s over up to 100 meters of Cat 5e cable, in both directions at once, every time. Wi-Fi's real speed depends on distance, walls, channel width and how many other devices are taking turns.
  • Latency and jitter. A wired hop to the router takes well under a millisecond. Wi-Fi adds a few milliseconds, and more importantly the delay varies (jitter) because of backoff and retransmissions. Video calls, games and remote desktop feel jitter more than they feel raw speed.
  • Loss. Wi-Fi quietly retransmits lost frames at layer 2, which hides loss as delay. When the signal is marginal, that shows up as stutter.
  • Sharing. Each switch port is its own link. Every device on a Wi-Fi channel shares one.

The rule of thumb: anything that doesn't move and is near a jack should be wired, especially a desktop, a game console, a TV, a NAS, and above all the link between mesh points. Wi-Fi is for things that move. If you can't run cable, powerline and MoCA (Ethernet over the coax already in your walls) adapters are worth a look; they are bridges too, so they add no NAT.

Look for yourself

Reading your own setup

Three commands tell you most of what you need: your address, your default gateway, and the first few routers out of the house.

Your address and gateway. On Windows, open a terminal and run ipconfig. Find the adapter you're actually using (Wi-Fi or Ethernet; ignore the virtual ones for now, Chapter 12 deals with them) and read three lines:

Wireless LAN adapter Wi-Fi:
   IPv4 Address. . . . . . . . . . . : 192.168.86.57
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.86.1

On Linux, ip addr shows addresses and ip route shows the gateway in a line like default via 192.168.86.1 dev wlan0. On macOS, ipconfig getifaddr en0 prints the Wi-Fi address and route -n get default prints the gateway. The default gateway is your router's LAN address: the first box that will change your packets.

The first hops out. Now ask every router on the way out to identify itself. On Windows, tracert -d -h 5 example.com (-d skips name lookups so it's faster, -h 5 stops after five hops); on macOS or Linux, traceroute -n -m 5 example.com. Each line is one router, found by sending packets with TTL 1, then 2, then 3, and listening for the "time exceeded" messages that come back.

Tracing route to example.com [198.51.100.80]
over a maximum of 5 hops:
  1     3 ms     2 ms     3 ms  192.168.86.1
  2     4 ms     4 ms     5 ms  192.168.1.1
  3    12 ms    11 ms    13 ms  203.0.113.1
  4    14 ms    13 ms    15 ms  198.51.100.9
  5    15 ms    14 ms    14 ms  198.51.100.80

Read the addresses, not the times. Hop 1 is your own router. Then count how many hops in a row have private addresses: 10.x.x.x, 172.16–31.x.x or 192.168.x.x. One private hop is normal. Two private hops, as above, mean a router behind a router: double NAT. A hop in 100.64–127.x.x right after them points to carrier-grade NAT. The first public address is the ISP's side of the border. Notice what never shows up: the switch, the access point and the mesh points. They don't touch TTL, so traceroute can't see them.

Go deeper: more ways in

ipconfig /all on Windows adds each adapter's MAC address, its DHCP server and lease times, and its DNS servers. If the DHCP server and the default gateway are the same address, that's your router. route print shows the full routing table, and PowerShell's Get-NetIPConfiguration gives a tidy per-adapter summary.

Then open the router's admin page: type the default gateway address into a browser. Its status page shows the WAN address it received. If that WAN address is itself private (say 192.168.1.20), this router sits behind another one, and you've found double NAT from the other end. If it's in 100.64.0.0/10, the "other router" is your ISP's.

Windows tracert sends ICMP echo requests; the Unix traceroute sends UDP packets to high port numbers by default. Some routers ignore one kind or rate-limit their replies, which shows as * for a hop. A star is not necessarily a failure. Chapter 13 covers reading traceroutes properly.

Instrument 2

Where does this packet go?

Follow one packet from a laptop to a website, a hop at a time. The card shows the frame's outer envelope (layer 2) and the packet inside (layers 3 and 4); anything that changed at this hop is highlighted, with its old value underneath. Each NAT keeps a real translation table, so open a second connection, or have the phone use the same port, and watch the router pick a different one. Then send the reply back, or try an unsolicited packet from outside.

Hop–
Layer–
TTL–

MAC addresses are invented, locally administered ones. The internet core is shown as one stop that lowers TTL by five, standing in for five routers.

A preview of Chapter 08

Spotting a second router

Double NAT is easy to create and easy to miss, because ordinary browsing works fine through it. Every outbound connection gets translated twice and the replies find their way back through both tables. The problems only show up when something needs to come in, or when two devices want to find each other directly.

The symptoms, in roughly the order people notice them:

  • Two private hops in a traceroute, like 192.168.86.1 then 192.168.1.1.
  • A private WAN address on your router's status page.
  • Port forwarding "doesn't work." You set it up on your router, but the outside world only reaches the ISP gateway, which has no matching rule. You'd need a forward on both.
  • Automatic port mapping fails. Game consoles and peer-to-peer apps ask the router to open a port with UPnP, NAT-PMP or PCP. Your router opens it, but only on its own NAT; the gateway in front never hears about it. Apps report "strict" or "type 3" NAT.
  • Devices on the two networks can't see each other. A printer or TV plugged into the ISP gateway lives on 192.168.1.x; your laptop on the mesh is on 192.168.86.x. Discovery that relies on broadcast or multicast, like casting and printer sharing, can't cross the router between them.
  • Peer-to-peer links fall back to relays. Tools that try to connect two devices directly, as video calls, games and Tailscale do, have a harder time punching through two NATs and more often end up relaying traffic through a server, which adds delay.

That last one is the case that started this site. A Windows laptop on a mesh network at 192.168.86.x, behind an ISP gateway at 192.168.1.x, kept retrying NAT-PMP port-mapping requests, and its Remote Desktop sessions over Tailscale ran through a DERP relay instead of the direct path. Every screen update made a round trip through a distant server. The fixes are the same as for any double NAT: put one of the two boxes in bridge or access-point mode so only one does NAT, or, if the ISP box can't be bridged, use its "IP passthrough" or DMZ setting to hand everything to your router. Chapter 08 takes it apart properly, and Chapter 09 explains the direct-versus-relay decision.

Go deeper: bridge mode, AP mode, passthrough, DMZ

Bridge mode on an ISP gateway turns off its router, NAT, DHCP server and usually its Wi-Fi, and passes the public address through to whatever is plugged into it. The gateway becomes a modem. Your router then gets the public address and is the only NAT.

Access point mode (some brands say "bridge mode" here too, confusingly) is the same idea from the other side: your own router or mesh stops routing and simply extends the ISP gateway's network over Wi-Fi. Only one NAT remains, but the ISP box is in charge of DHCP and the firewall, and some mesh features need router mode to work.

IP passthrough (the name varies by ISP) keeps the gateway's router running but gives your router the public address anyway. DMZ host is weaker: the gateway still does NAT but forwards every unsolicited inbound port to one inside address, your router. It fixes inbound forwarding but leaves the double translation in place.

Cheat sheet

Terms from this chapter

Modem / ONT
Translates the ISP line's signal (coax, phone line, fiber) to Ethernet. Layers 1–2; makes no address decisions.
ISP gateway
An all-in-one box: modem, router, NAT, DHCP, DNS forwarder, firewall, switch and Wi-Fi.
Router mode / bridge mode
Whether a box routes and does NAT, or just passes frames through as a layer-2 bridge.
WAN / LAN port
The router's outside-facing port, and its inside-facing ports.
Default gateway
The router your device sends everything that isn't local to. Usually the router's LAN address.
Switch
Layer-2 box that learns which MAC address is on which port and forwards frames only there.
Access point
A radio bridge between Wi-Fi and the wired LAN. Doesn't change IP headers.
Mesh / backhaul
Cooperating access points under one network name; the backhaul is the link between them, wired or wireless.
Channel
A slice of a Wi-Fi band. At 2.4 GHz, only 1, 6 and 11 avoid overlapping in North America.
Double NAT
Two routers in a row, both translating addresses. Outbound works; inbound and peer-to-peer suffer.
CGNAT
Carrier-grade NAT: the ISP translates too, using 100.64.0.0/10 between itself and your router.
Where the facts come from

Sources

  1. RFC 1812, Requirements for IP Version 4 Routers (forwarding, TTL decrement, ICMP time exceeded). rfc-editor.org/rfc/rfc1812
  2. RFC 791, Internet Protocol (the IPv4 header and time-to-live field). rfc-editor.org/rfc/rfc791
  3. RFC 1918, Address Allocation for Private Internets (10/8, 172.16/12, 192.168/16). rfc-editor.org/rfc/rfc1918
  4. RFC 6598, IANA-Reserved IPv4 Prefix for Shared Address Space (100.64.0.0/10 for carrier-grade NAT). rfc-editor.org/rfc/rfc6598
  5. RFC 3022, Traditional IP Network Address Translator; RFC 4787, NAT Behavioral Requirements for Unicast UDP (address and port mapping, port preservation). rfc3022 · rfc4787
  6. RFC 2131, Dynamic Host Configuration Protocol; RFC 1034 and 1035, Domain Names. rfc2131 · rfc1034 · rfc1035
  7. RFC 7084, Basic Requirements for IPv6 Customer Edge Routers; RFC 6092, Recommended Simple Security Capabilities in Customer Premises Equipment for Providing Residential IPv6 Internet Service; RFC 8415, DHCP for IPv6 (prefix delegation). rfc7084 · rfc6092 · rfc8415
  8. RFC 6886, NAT Port Mapping Protocol (NAT-PMP); RFC 6887, Port Control Protocol (PCP). rfc6886 · rfc6887
  9. IEEE 802.3, Ethernet (1000BASE-T, full duplex); IEEE 802.1D / 802.1Q, Bridges (MAC learning); IEEE 802.11, Wireless LAN (frame addressing, CSMA/CA, channel plans). standards.ieee.org/ieee/802.3 · standards.ieee.org/ieee/802.11
  10. ITU-T G.984 series, Gigabit-capable passive optical networks (GPON); CableLabs, DOCSIS specifications. itu.int/rec/T-REC-G.984.1 · cablelabs.com/specifications
  11. Microsoft Learn, ipconfig, tracert and route command references. ipconfig · tracert
  12. Tailscale, How NAT traversal works and DERP servers (direct versus relayed connections, 100.64.0.0/10 addressing). tailscale.com/blog/how-nat-traversal-works · tailscale.com/kb/1232/derp-servers
  13. waves.jelia.nyc, 2.4 GHz, for the radio physics behind Wi-Fi. waves.jelia.nyc/2-4-ghz
  14. RFC 5737, IPv4 Address Blocks Reserved for Documentation (every public address shown here). rfc-editor.org/rfc/rfc5737